Terminal Escape Sequence Injection Vulnerability in Onefetch by o2sh
CVE-2026-100866

4.8MEDIUM

Key Information:

Vendor

O2sh

Status
Vendor
CVE Published:
27 September 2026

What is CVE-2026-100866?

Onefetch versions up to 2.28.1 are susceptible to a terminal escape sequence injection vulnerability. This issue arises from the improper handling of repository information field values, which are outputted to the terminal without the necessary sanitization to remove control characters. Consequently, attackers can exploit this flaw by injecting ANSI/OSC escape sequences into the project manifest version and name fields. When a user runs Onefetch, these escape sequences can manipulate the terminal output, enabling the potential to rewrite window titles, hide text, or invoke emulator-specific actions, thereby compromising the security and usability of the terminal environment.

Affected Version(s)

onefetch 0 <= 2.28.1

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.